Have you ever picked up the phone to hear the following: "I'm calling from Microsoft. We've had a report from your Internet service provider of serious virus problems from your computer"? Of course the caller offers to help, offering a free scan, which invariably leads to warnings over mass malware infections, and the offer of paid technical support to assist.

Security professionals know to steer clear of such scams. Since they persist, scammers are apparently tricking sufficient numbers of consumers into forking over their cash--$250 or more, in some cases--to fix the virus infections identified by the caller's in-house technicians. Windows phone scams--targeting PC owners--appear to have begun in earnest in 2008, and been on the rise ever since, according to the Guardian. Meanwhile, their popularity is fueled by "the availability of cheap phone calls and labor in countries like India," according to Which?, a U.K. consumer rights group.

To fight back, many people try to tie up the cold callers on the phone for as long as possible, or even provide them with fake credit card numbers. But after receiving repeat calls, one malware researcher decided to see what exactly the scammers were doing by granting them access to his virtual test machines, which he used to record their activities. "The goal was to find out who they were and exactly what the scam was. Luckily I was able to get hold of information such as their internal IP addresses, the PayPal accounts used to wire money, and the numbers they are calling from," said Kaspersky Lab security researcher David Jacoby in a blog post.

1. Caller Claims To Be With Microsoft
Microsoft support scams are a type of social engineering attack, which succeeds not through attackers' technical sophistication, but rather by tricking people via smooth talking and playing on their fears. In Jacoby's case, he said the caller pretended to be from a department--non-existent, by the way--at Microsoft that was following up indications that his computer was either broken or had been infected by malware.

2. Windows Errors Easy To Find
To make the case that his PC showed signs of malware infection, Jacoby said the woman who called him instructed him to open the Windows Event Manager, so that he could see numerous error messages which she said indicated that his system had been compromised. "The event viewer does show error messages, but not directly related to an infection," said Jacoby. "Almost all computers have errors in the log files, especially if the computer has not been re-installed lately and is running a lot of programs."

3. Windows Processes Used For Sleight Of Hand
Jacoby said the scammer then instructed him to execute a DOS command to reveal the system's unique ID and allow her to verify that it was referencing the correct--infected--system. The caller then read out the license ID, and asked Jacoby if it matched the ID he was seeing on his screen. It did, but that was because the DOS command he'd run revealed the ID for a file extension that ships on all Windows PCs. The caller then instructed him to run the "verify" DOS command to see if his Windows license could be verified, and said that an "off" setting--which Jacoby saw--would indicate that the license couldn't be verified. But in reality, this setting is only used to "enable/disable operating system verification that data has been written to disc correctly," he said, and has nothing to do with the Windows license.

4. Scammers Wield Drama
But after the second DOS command returned an "off" response, Jacoby said the caller began "screaming 'oh my god!' in my ear, she was super upset that my license was not verified; according to her this meant that no security patches could be installed." After recommending that Jacoby allow her technician to directly access his PC, he agreed. "I was running everything in an empty virtual machine," he said, and found that the organization offering to repair his PC was using free--and on its own, legitimate--remote-administration software known as AMMYY.

5. Remote Access Scans Trigger Falsehoods
While he was still on the phone with the caller, Jacoby watched as the remote access tool administrator--on his PC screen--opened an old certificate, which said that it dated from 2011. At this point, the woman who had called him claimed that his PC hadn't been updated since 2011, and told him that he needed "to install security software which will protect me against viruses, malware, Trojans, hackers, and other things." He agreed, and watched as an application ("G2AX_customer_downloader_win32_x86") was installed and run on his PC, which indicated that he had "successfully updated the software license for lifetime."

6. Social Engineering Tricks The Scammers
After the supposed fix, and with the caller still on the line, Jacoby was given a PayPal account into which he was supposed to pay $250. When the fake credit card data that he supplied to the caller didn't work, he asked the caller to browse to a website where his friend, he said, had left credit card data in plain text. After the caller browsed there, he captured her IP address, disconnected the call, and reviewed which phone numbers the caller had used. "After collecting all the information, I have now contacted all the appropriate people, such as the security team at PayPal [and] various law enforcement agencies with the hope that we can stop these people," said Jacoby.

7. Scammers Avoid Attack Software
To recap, the Microsoft Windows malware phone scam succeeds in part because it's a social engineering attack: Callers tell Windows owners to input a few commands into their PC, then "interpret" the results to highlight how the system is infected with malware. Furthermore, the remote-access tool used by scammers typically doesn't trip any security alarm bells, because such tools can be used for benign purposes, such as actual customer support. "The software that they were using was not malicious in any way, which means that no security software can detect these types of scams," he said.

Jacoby, of course, had a test machine at the ready, which was devoid of any sensitive information. The average business users or consumers, however, typically have some type of sensitive data stored on their PC. In other words: don't try this type of security research at home. "If you ever get a call 'from Microsoft' stating that there are some indications that your computer is broken or infected--please hang up," he said.

I don't use caller ID. I have been called repeatedly by these jerks, and yes, I was also told that I would be F%$D by one who claimed to be a terrorist from Pakistan, and that if I did not do what he said my house would go BOOM! The last call I got from someone who asked me if I had paid.

I did not bother to call the police as I have never found them to be helpful. The NC state attorney general doesn't seem to know what to do about any scam calls at all including the ones to lower my interest rate on my non-existent credit cards.

Hi Satya, I'm sorry your migration is not going well. We'll try to help you, but you may get quicker results by searching on the Microsoft Technet site. Have you tried that? The link is here: http://technet.microsoft.com/en-us/ms772425.aspx

When Inserting/Updating any records on any page, the record will get affected in database. But, after some time the effect of these records disappears from Database. i.e. The records I have inserted gets deleted from Database, and the records I have updated shows previous values. It seems like some process is rolling back these records after Insert/Update operation is performed

Excellent, I'm glad to hear it. It's good that you were vigilant and paying attention. Even with a Mac, the hackers keep getting more clever ;) And they are really bold, if they call you up pretending to be the Spanish government!

He says he's from the mac users department of microsoft in behalf of the spanish government (I Live in spain) and that they are receiving hundreds of messages from my computer because it's infected.

THey ask me to install teamviewer (for remote access) and I agree... they go to safari then and install "mackeeper"... this began to sound weird at that moment.

THen mackeeper shows me , as I was hoping, that I have more than 2000 junk files and files in other idioms that are keeping space from my hard drive.

Then the indian guy begin to shout "OMG YOU ARE SO INFECTED!! ¿?¿?

I almost laugh and he ask me to open a textedit and he begin to write how badly my computer is infected and that he is going to install updated certificates because IT's illegal to have a computer with outdated certificates.

I then ask him why do they have my data... and he gets angry, he tells me he is going to install those certificates for my safety and then I stop the teamviewer call.

He gets very angry and he tells me that he is going to block my computer.

I tell him "perfect, so I won't work today" and he insist on blocking my computer saying "ok, wait a second I'm blocking your computer now..."

I laugh and try to hung the phone but here's the tricky part: I couldn'! they called me, but I was trying to hung the phone call and they were still at the other side.

I've been called a couple of times now from some guy with a heavy Indian accent stating that my computer was sending Microsoft error messages and he was calling to fix them.The first time he called I was a little suspicious right from the beginning.Then he wanted me to let him use remote desktop to access my PC.At that point I just hung up the phone.Then a month later I get a call again.The first time he forgot to hide his caller ID which is 011 56 42 311 5411 Chillan, Biobio.He hung up and immediately called me back.The 2nd time I played along for a little bit and then hung up.After reading some other posts here I'm quite sure that this is nothing but some kind of scam.AR

Recently, I called Microsoft phone support, directly from http://support.microsoft.com/contactus/ about my email having a problem. The solution which was figured out later was simply that I needed to empty space in my mail box. But my cousin helped me figure that out. I use outlook.com, a service they don't offer phone support for.Anyhow, I wasn't shy to show that I was mind boggled that phone support did not support products they still support... I still don't get that. Regardless, the guy from Microsoft phone support ended up giving me a phone number. He said it was outlook.com support. But, he said there's no phone support for it at first, so.... What is this?

I called. What a mistake. The guy ran through my computer quickly to show it's being used as a bot and I'm one of the people who has the infamous "Zeus" malware. I needed some guy to come and manually code 7 things or something and it'd cost money of course to get rid of this horrible virus.I panicked, got the guy off my computer, and scanned several times with several security products, and even grabbed RUBotted to find out I don't have it.

OFFICIAL MICROSOFT PHONE SUPPORT DIRECTED ME, EVEN OFFERED TO REDIRECT THE LINE FOR ME, TO CONTACT A SCAM COMPANY.I sh*t you not.

Our latest survey shows growing demand, fixed budgets, and good reason why resellers and vendors must fight to remain relevant. One thing's for sure: The data center is poised for a wild ride, and no one wants to be left behind.